SSL and the Future of Authenticity
Offered By: LASCON via YouTube
Course Description
Overview
Syllabus
Intro
picture
hack -- war
What does this mean?
How would they use them?
referrer
early 90's
e-commerce
web applications
billion
million
intense pressure
4am decisions == javascript
entirely theoretical
cyber war
happening every day
Mike Zussman just asked for it.
State Sponsored?
good news
problem?
What happened to Comodo?
ideological
browser vendors
trust agility
one decision for everyone?
our data, our trust decision
SSL Cert -- DNS Record
information -- distributed
trust -- centralized
DNSSEC == CA System
domain seizures
COICA, PROTECT IP, etc...
forever
user initiated
implementation
self-signed certs
initial connection
eliminate CAs entirely
notary lag
CONVERGENCE
+ privacy
Servers Do Nothing
no more self-signed certificate warnings
problems
captive portals
Taught by
LASCON
Related Courses
Comparing WAF and RASP - Why?LASCON via YouTube API Security - Is it the New Application Attack Surface and How to Secure at Enterprise Scale
LASCON via YouTube Privacy Impact Assessments - How Much Privacy Is Enough?
LASCON via YouTube Your Frontier Defense - Understanding Web Application Firewalls
LASCON via YouTube Doing This One Crazy Thing Will Change Your AppSec Program Forever
LASCON via YouTube